Sign in

GrapheneOS

@grapheneos.org
20K followers 0 following 6.3K posts

Open source privacy and security focused mobile OS with Android app compatibility. grapheneos.org

PostsRepliesMedia
GrapheneOS @grapheneos.org · 12/09/2026
Here's a screenshot showing how it was before we made the post. There are still tons of flagged comments going back a couple weeks. Help appreciated.
1241
GrapheneOS @grapheneos.org · 26/06/2026
Our update servers are sponsored by Mullvad, ReliableSite, Cherry Servers, Zare and Xenyth. You can see those here: grapheneos.org/articles/gra... The screenshot shows bandwidth usage for Frankfurt with staggered rollout to 10th gen, then 9th, then 8th and finally 7th+6th together.
Graph of bandwidth usage for fra.grapheneos.org over the past 8 hours showing 20.63Gbps 95th percentile bandwidth usage.
0320
GrapheneOS @grapheneos.org · 05/04/2026
Gaël Duval is the founder and president of the /e/ foundation along with the CEO of Murena. Duval and his organizations have consistently taken a stance against protecting users from exploits. In this video, he once again claims protecting against exploits is for only useful pedophiles and spies.
1015740
GrapheneOS @grapheneos.org · 28/04/2025
@BakuretsuMajou is someone else who was trying to support us by linking to a video from another content creator who was supporting us. They were replying to @anomalous.dev's messages linking Rossmann's content. We don't recommend that video as a debunking of this stuff, it wasn't high effort.
X screenshot showing replying to the post linked above which shows 
that it's a reply to @BakuretsuMajou and @57_Wolve. It also shows @BakuretsuMajou was replying to 2 deleted messages.
000
GrapheneOS @grapheneos.org · 12/03/2025
As a preview of what's going to be possible in the upcoming release of GrapheneOS, here's a screenshot from a Pixel Tablet running desktop Chrome in a virtual machine with basic GPU acceleration via ANGLE on the host. The infrastructure is a lot more robust than the Terminal app.
Full screen Chromium window with a single tab for chrome://gpu showing GPU acceleration is working.
1376
GrapheneOS @grapheneos.org · 18/12/2024
This issue has been misinterpreted by a paper published on 2023-11-27 as being Vanadium-specific. It also misunderstands the issue. Chromium generates a random number to use as a salt to protect privacy. We think this may be reducing privacy. It is not a hardware identifier.
Looming over the prospect of Vanadium’s claim to privacy, GitHub Issue #181, raises significant
concern regarding the exposure of unique hardware IDs. The issue describes a vulnerability where devices
might leak a distinct fingerprint due to the exposure of hardware-related information. While a solution to
hardcode WebRTC device_id_salt has been proposed to mitigate this issue (Flawedworld, 2023), it has
not yet been implemented. This unresolved challenge is of particular relevance to our study, as it suggests
that the entropy of browser fingerprints for GrapheneOS users could be considerably higher than its
mainstream counterparts, and, in the worst case, render Vanadium ineffective for private browsing.

When a software exposes hardware IDs, it reveals far more unique user data than canvas
fingerprinting. Like a MAC address, such hardware identifiers are low-level and persistent unless changed,
which should triage the hardware ID issue with priority in the Vanadium backlog. The methods outlined in
publications prior are certainly capable of measuring hardware IDs, and should be reapplied to audit the
Vanadium and Jelly browsers. With mainstream browsers already implementing countermeasures like
fingerprinting alerts, it seems like GrapheneOS has sizable ground to cover.

As the digital ecosystem evolves, the methods of fingerprinting and fingerprinting prevention evolve
concurrently. Platforms like GrapheneOS stand at the vanguard of the privacy movement, and are certainly
expected to maintain the safeguards vital to user privacy. Considering the scope of fingerprinting
capabilities, it becomes clear that GrapheneOS is due for a security audit. Future research, especially
focusing on platforms like GrapheneOS's Vanadium, is not merely beneficial—but imperative; not only to
the technical user, but to those who actually have something worth hiding.
180
GrapheneOS @grapheneos.org · 21/07/2024
Here's the Cellebrite Premium 7.69.5 Android Support Matrix from July 2024 for overall Android devices. Other than the Titan M2 on the Pixel 6 and later not being successfully yet to bypass brute force protection, it's largely just based on what they've had time to support.
How to use the Support Matrix flow chartAndroid OS Access Support Matrix — Unlocked devicesAndroid OS Access Support Matrix — Locked devicesAndroid OS Access Support Matrix — Locked devices (cont.)
110
GrapheneOS @grapheneos.org · 21/07/2024
Here's the Cellebrite Premium 7.69.5 Android Support Matrix from July 2024 for Pixels. They're still unable to exploit locked GrapheneOS devices unless they're missing patches from 2022. A locked GrapheneOS device also automatically gets back to BFU from AFU after 18h by default.
Android OS Access Support Matrix — Google Pixel 1-5Android OS Access Support Matrix — Google Pixel 6-8
182
GrapheneOS @grapheneos.org · 21/07/2024
Here's the Cellebrite Premium 7.69.5 iOS Support Matrix from July 2024. 404media recently published an article based on the same April 2024 docs we received in April and published in May. Many tech news sites including 9to5Mac made incorrect assumptions treating that as current.
iPhones Support Matrix 7.69.5 LockediPhones Support Matrix 7.69.5 UnlockediPads Support Matrix 7.69.5
393
GrapheneOS @grapheneos.org · 02/07/2024
Unplugged in also infringing on the open source licensing multiple projects including DivestOS where they ripped off their AV from without attribution. They even still use DivestOS servers without permission. SkewedZeppelin is lead developer of DivestOS (URLs are in alt text):
Reply from SkewedZeppeling on October 2023:

Big no for a litany of reasons.

Their Anti-Virus is a GPL violating fork of my Hypatia and they even still download databases from my server: https://www.virustotal.com/gui/file/a461f8194554fd92d83a1aff20fa48f730a99e7679e1f1bbfc6935e1b049aafb/details

See also the questionable apps they have: list of apps on the unplugged "app store" returned from /api/store/app?size=10000 https://gist.github.com/aemmitt-ns/ad3f1d3ff34c36c0206fe6216fd56e19
140
GrapheneOS @grapheneos.org · 23/06/2024
GrapheneOS Info app is now available through our app repository and will be included in the next release of the OS. It supports viewing recent OS release notes, provides info on our chat rooms, forum and active social media accounts along with offering all the donations methods.
Screenshot of the GrapheneOS Info app showing the latest 2024061400 release notes in the Release Notes tab. It also has tabs for Community and Donate. It's a modern Material 3 app design with Material You support.
1185
GrapheneOS @grapheneos.org · 18/05/2024
Cellebrite has similar capabilities for iOS devices. This is also from April 2024. We can get the same information from newer months. In the future, we'll avoid sharing screenshots and will simply communicate it via text since to prevent easily tracking down the ongoing leaks.
Capability table described by the tweet. We can't properly format the tabular data as alt text but we can share it elsewhere.Capability table described by the tweet. We can't properly format the tabular data as alt text but we can share it elsewhere.
1131
GrapheneOS @grapheneos.org · 18/05/2024
Cellebrite's list of capabilities provided to customers in April 2024 shows they can successfully exploit every non-GrapheneOS Android device brand both BFU and AFU, but not GrapheneOS if patch level is past late 2022. It shows only Pixels stop brute force via the secure element.
Capability table described by the tweet. We can't properly format the tabular data as alt text but we can share it elsewhere.Capability table described by the tweet. We can't properly format the tabular data as alt text but we can share it elsewhere.
1212
GrapheneOS @grapheneos.org · 05/11/2023
This is a preview of App Communication Scopes from an incomplete proof of concept we made for a previous version. The goal is to provide the ability to disable communication with user installed apps within a profile with the ability to enable it on a case-by-case basis instead.
Screenshot of "Restrict app communication" user interface showing a toggle for restricting app communication for an app which is currently enabled followed by toggles for each user installed app to permit communication between them.
141
GrapheneOS @grapheneos.org · 13/10/2023
Wise sent us an email 4 hours ago informing us that our US bank account information has changed without warning. They changed bank partners in the US. We've updated the donation page at grapheneos.org/donate#wise-us. If you use the old information or your donation will get refunded.
Your local USD account details have changed.
Due to an operational change, your local USD account details for your Wise Business account have changed. To avoid any delays sending or receiving USD payments, it’s important that you take action:
• Stop using your existing USD account details immediately as they will no longer work
• Share your new details with any third parties that send you money.
• Change your invoice templates and update any accounting software you use.
• Update any direct debits you have authorised.
• Update any platforms you use to receive payments, like Amazon or Stripe.
• Update your online banking if that’s how you add money to your Wise account.
You can find your new account details in your USD balance. Log in to your business account to see them, or just click below.
See your updated USD account details
Your old local USD account details will not work as of October 13, 2023. After that, any payments sent to these details will automatically be refunded to the sen
041